The package has a clear MIT license, tests, documentation, and a focused dependency set. Its small organization-backed project is not archived, but maintenance and security-process evidence are limited.
58%
Total Score
75
100
79
75
The latest release was about 19 months ago, with no releases in the last 12 months. That is a meaningful maintenance concern for a package consumers may depend on.
The repository recorded 0 commits and 0 active maintainers over the last 3 months. The project is not archived, but recent upkeep is absent.
Composer build tooling is present, but no security scanning tools were detected. That is a modest process gap for a dependency distributed to other projects.
The repository has no security policy. This limits transparency about how vulnerabilities are reported and handled, although it does not by itself show a security flaw.
Version v0.2.6 is not a stable-major release, so compatibility expectations are lower than for a 1.x package. It is not marked as a prerelease, which partly offsets the concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0|^2.0 | — | — |
drewlabs/envoyer-contracts Version ^0.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.